At 08:40 PM 5/6/2002, Edwards, David (JTS) wrote: >Hi, > >We've just found some instances of "netbuie.exe" running in some terminal >server sessions here. The file was written to the Winnt\system32 directory >about 6:00pm on Sunday and registry entries made in: > >HKLM/Software\Microsoft\windows\current version\run >HKLM/Software\Microsoft\windows\run As you suspected, appears that NetBUIE.exe is a scumware Trojan that has been posted up on the Web as a Microsoft Xbox emulator: http://www.newsbytes.com/news/02/176472.html Brian ---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com
This archive was generated by hypermail 2b30 : Thu May 09 2002 - 08:32:22 PDT